CVE-2025-32290: WordPress Sticky HTML5 Music Player plugin <= 3.1.6 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Sticky HTML5 Music Player allows SQL Injection. This issue affects Sticky HTML5 Music Player: from n/a through 3.1.6.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Sticky HTML5 Music Player lbg-audio3-html5 allows SQL Injection.This issue affects Sticky HTML5 Music Player: from n/a through <= 3.1.6.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32290?
CVE-2025-32290 has a high severity rating due to the potential for SQL Injection attacks.
How do I fix CVE-2025-32290?
To fix CVE-2025-32290, update the Sticky HTML5 Music Player to a version later than 3.1.6.
What systems are affected by CVE-2025-32290?
CVE-2025-32290 affects versions of the Sticky HTML5 Music Player from n/a through 3.1.6.
What type of vulnerability is CVE-2025-32290?
CVE-2025-32290 is an SQL Injection vulnerability that allows attackers to manipulate SQL queries.
Is CVE-2025-32290 easy to exploit?
Yes, CVE-2025-32290 can be easily exploited if proper input validation is not implemented.